CWE-20
12,840 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,840)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API ca...Show more |
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administr...Show more |
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. |
Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. |
2Debian Inspircd2Debian Linux InspircdMay 6, 2026 Apr 12, 2016 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) char...Show more |
1Huawei 5S5300 Firmware S5700 FirmwareS7700 Firmware+2 moreMay 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic. |
5Canonical DebianOpensuse+2 more10Communications Billing And Revenue Management Configuration ManagerDatabase Server+7 moreMay 6, 2026 Apr 8, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp. |
The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547. |
Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the...Show more |
2Debian Rubyonrails3Debian Linux RailsRuby On RailsMay 6, 2026 Apr 7, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method. |
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando. |
2Jenkins Redhat2Jenkins OpenshiftMay 6, 2026 Apr 7, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspec...Show more |
2Fedoraproject Nodejs2Fedora Node.jsMay 6, 2026 Apr 7, 2016 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection...Show more |
2Fedoraproject Nodejs2Fedora Node.jsMay 6, 2026 Apr 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header. |
Huawei Sophia-L10 smartphones with software before P7-L10C900B852 allow attackers to cause a denial of service (system panic) via a crafted application with the system or camera privilege. |
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
2Cisco Sun3Evolved Programmable Network Manager OpensolarisPrime InfrastructureMay 6, 2026 Apr 6, 2016 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID...Show more |
1Cisco 2Asa With Firepower Services Firesight System SoftwareMay 6, 2026 Apr 1, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726. |
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug...Show more |
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL an...Show more |